exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 214 discussion

Actual exam question from Isaca's CISM
Question #: 214
Topic #: 1
[All CISM Questions]

Which of the following provides the BEST assurance that a contracted third-party provider meets an organization's security requirements?

  • A. Continuous monitoring
  • B. Due diligence questionnaires
  • C. Right-to-audit clause in the contract
  • D. Performance metrics
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
DelTrotter
Highly Voted 2 years, 2 months ago
Selected Answer: C
Right to Audit.
upvoted 7 times
...
[Removed]
Highly Voted 1 year, 7 months ago
Selected Answer: A
In the "CISM Review Manual 15th Edition" by ISACA, it is stated in Domain 4: Incident Management and Response, that continuous monitoring is a critical part of the overall incident management process, and it extends to monitoring third-party providers to ensure they meet the organization's security requirements.
upvoted 5 times
...
hohan
Most Recent 1 month, 2 weeks ago
Selected Answer: A
In the "CISM Review Manual 15th Edition" by ISACA, it is stated in Domain 4: Incident Management and Response, that continuous monitoring is a critical part of the overall incident management process, and it extends to monitoring third-party providers to ensure they meet the organization's security requirements.
upvoted 2 times
...
RagazzoAlex
7 months, 2 weeks ago
Selected Answer: A
Continuous versus periodic verification --> Continuous will always be better
upvoted 1 times
...
oluchecpoint
1 year, 1 month ago
Selected Answer: C
C. Right-to-audit clause in the contract
upvoted 1 times
...
AlexJacobson
1 year, 1 month ago
Selected Answer: C
Right-to-audit clause can include continuous monitoring. Audit =/= periodic (people get stuck with this). It's like you enable auditing of specific action or a file system in the OS. It's not periodic, it's constant (and you can call it continuous monitoring).
upvoted 2 times
Josef4CISM
3 months, 3 weeks ago
Makes sense, thanks!
upvoted 1 times
...
...
Uncle_Lucifer
1 year, 2 months ago
Selected Answer: A
To be frank A is the best answer. Continuous versus periodic verification --> Continuous will always be better A is better than C. Answer is --> A
upvoted 1 times
...
Learner76
1 year, 3 months ago
If someone read this. When do we use "Right to Audit"?
upvoted 1 times
Uncle_Lucifer
1 year, 2 months ago
you can audit them when needed. The right to audit clause is included in the contract.
upvoted 1 times
...
...
CISSPST
1 year, 5 months ago
I understand that audit and assurance go hand in hand. However, if we have to pick between audit and continuous monitoring, I'd pick monitoring. Audit will provide the snapshot of the state of security at a specific time, which can change post audit. Continuous monitoring will be required for ongoing assurance. Answer: A
upvoted 1 times
...
oluchecpoint
1 year, 6 months ago
C. Right-to-audit clause in the contract
upvoted 2 times
...
karanvp
1 year, 8 months ago
C may be wrong because the audit will not happen not so frequently, hence making sure assurance all time is not possible
upvoted 4 times
...
richck102
1 year, 9 months ago
i vote .....C. Right-to-audit clause in the contract
upvoted 1 times
...
DASH_v
1 year, 9 months ago
Selected Answer: A
A for sure, it's the only method to assure while audit can not since vendor can alter controls after the audit is closed. Besides, continuous monitoring generally performs after an audit or security assessment, why it is called "continuous monitoring" but not just "monitoring"
upvoted 1 times
...
sedardna
1 year, 9 months ago
Selected Answer: B
Auditoría siempre como principio de SLA
upvoted 1 times
...
mad68
1 year, 9 months ago
Selected Answer: C
Continuous monitoring helps in ongoing oversight, but it may not cover all aspects of security requirements. Due diligence questionnaires provide initial information, but they may not be sufficient to validate the provider's security practices comprehensively. Performance metrics can indicate the provider's performance but may not directly address security requirements.
upvoted 2 times
...
Dravidian
1 year, 10 months ago
All these questions are so ambiguous. So much room for assumptions and interpretation. Continuous monitoring can give assurance but the best assurance is an audit. But a right to audit clause means nothing unless an audit is conducted in which case continuous monitoring gives better assurance than right to audit clause.
upvoted 1 times
...
Abhey
1 year, 10 months ago
The right-to-audit clause in the contract provides the BEST assurance that a contracted third-party provider meets an organization's security requirements. This clause grants the organization the right to perform audits or inspections of the third-party's facilities, personnel, systems, or documentation. By exercising this right, the organization can confirm that the third-party is complying with security requirements and can identify any security gaps or deficiencies. Continuous monitoring, due diligence questionnaires, and performance metrics are all useful measures, but they cannot provide the same level of assurance as a direct audit.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago